VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.4.128 fixes CVE-2020-14969 ACL flaw

routine vulnerability

MISP 2.4.128 patches an attribute correlation ACL bypass and refactors STIX import/export with new features.

MISP, the open-source threat intelligence platform, released version 2.4.128 with a major refactoring of STIX 1 and 2 import/export functionality, contributed by Christian Studer. The update automatically maps imported threat-actors, tools, and other data points to existing MISP galaxy entries by matching synonyms, improving interoperability when ingesting STIX-formatted threat intelligence.

The release also addresses CVE-2020-14969, a security flaw in app/Model/Attribute.php affecting MISP versions up to 2.4.128, where the attribute restsearch API lacked proper ACL lookup on attribute correlations, potentially exposing metadata about correlating but otherwise unreachable attributes. Additional improvements include CIDR-based correlation support for ip-src|port and ip-dst|port attribute types, and a new authentication failure dashboard widget sourced from the D4 project. This is a routine maintenance and feature release with no evidence of active exploitation.

Mentioned in this report

Vulnerabilities CVE-2020-14969

Source reporting: https://www.misp-project.org/2020/06/24/misp.2.4.128.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free